اشكرك اخي بوب
عملت فحص بالبرنامج الاول ولم يعيد تشغيل الجهاز لكن ظهر هذا التقرير
ComboFix 08-06-10.5 - xxx 06/12/2008 14:59:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.97 [GMT 3:00]
Running from: C:\Documents and Settings\xxx\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com
.
((((((((((((((((((((((((( Files Created from 2008-05-12 to 2008-06-12 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-12 12:04 680,480 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-12 12:04 28,098,592 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-12 11:58 --------- d-----w C:\Documents and Settings\xxx\Application Data\DMCache
2008-06-11 04:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-11 04:04 65,408 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-11 04:04 376,976 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-05 12:48 --------- d-----w C:\Program Files\Common Files\xing shared
2008-06-05 12:47 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-06-05 12:47 --------- d-----w C:\Program Files\Common Files\Real
2008-05-30 11:26 88,774 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-05-29 07:25 96,966 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-05-29 07:25 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-05-25 11:39 --------- d-----w C:\Program Files\Google
2008-05-23 08:09 --------- d-----w C:\Program Files\Project1
2008-05-23 07:56 286,720 ------w C:\WINDOWS\Setup1.exe
2008-05-21 11:30 --------- d-----w C:\Program Files\Avant Browser
2008-05-15 06:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-05-15 06:06 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-05-15 06:06 --------- d-----w C:\Program Files\Nokia
2008-05-15 06:06 --------- d-----w C:\Program Files\DIFX
2008-05-15 06:06 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-05-15 06:06 --------- d-----w C:\Documents and Settings\xxx\Application Data\PC Suite
2008-05-15 06:06 --------- d-----w C:\Documents and Settings\xxx\Application Data\AdobeUM
2008-05-13 04:37 --------- d-----w C:\Program Files\Collage Maker
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 07:34 --------- d-----w C:\Program Files\Hide IP Platinum
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-25 10:32 --------- d-----w C:\Program Files\Smoky City Design
2008-04-22 16:47 --------- d-----w C:\Program Files\DCEnhancer
2008-04-15 19:36 --------- d-----w C:\Documents and Settings\xxx\Application Data\ArcSoft
2008-04-15 19:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-15 19:34 --------- d-----w C:\Program Files\ArcSoft
2008-04-14 11:01 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2007-06-06 21:33 2,294,784 ----a-w C:\Program Files\FLV PlayerRCSetup.exe
2004-08-04 01:07 73,728 --sha-w C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
.
كود:
<pre>
----a-w 179,606 2005-10-06 12:48:34 C:\Documents and Settings\xxx\My Documents\برنامج تشفير لملفاتك فقط كليك يمين وشفرها\البرنامج + التعريب\التعريب .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [06/06/2007 12:25 PM 887040]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 04:07 AM 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [03/30/2006 04:45 PM 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GhostStartTrayApp"="C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe" [05/28/2003 07:11 PM 94208]
"Rscmpt"="C:\WINDOWS\system32\Rscmpt.exe" [08/25/2002 12:48 PM 481792]
"SMSERIAL"="sm56hlpr.exe" [10/08/2003 04:15 AM 548864 C:\WINDOWS\sm56hlpr.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [08/29/2007 10:43 AM 286720]
"SystemInit"="" []
"Karen"="" []
"raVe"="" []
"SystemBackup"="" []
"Win32BaseServiceMOD"="" []
"startIE"="" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/05/2008 03:47 PM 185896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"raVe"="" []
"Driver32"="" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 04:07 AM 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
BTTray.lnk - C:\Program Files\MSI\Bluetooth Software\BTTray.exe [2004-03-31 17:13:32 507965]
SnagIt 8.lnk - C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe [2007-05-01 11:11:48 6395464]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"vidc.ffds"= ffdshow.ax
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalStart.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalStart.lnk
backup=C:\WINDOWS\pss\PalStart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SnagIt 8.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SnagIt 8.lnk
backup=C:\WINDOWS\pss\SnagIt 8.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Start Menu^Programs^Startup^Tray icon for cleaner.lnk]
path=C:\Documents and Settings\xxx\Start Menu\Programs\Startup\Tray icon for cleaner.lnk
backup=C:\WINDOWS\pss\Tray icon for cleaner.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 01/19/2007 12:55 PM 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProxyCap]
C:\PROGRA~1\PROXYL~1\ProxyCap\ProxyCap.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 11/02/2004 08:24 PM 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 03/30/2006 04:45 PM 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Macromedia\\Flash MX\\Flash.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Avant Browser\\avant.exe"=
R1 GhPciScan;GhostPciScanner;C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys [05/28/2003 07:01 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/04/2007 02:58 PM]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [12/16/2006 11:37 PM]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-06-12 15:04:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 06/12/2008 15:10:05
ComboFix-quarantined-files.txt 2008-06-12 12:10:01
Pre-Run: 3,012,096,000 bytes free
Post-Run: 3,338,629,120 bytes free
173 --- E O F --- 2008-06-11 03:44:48